A hospital is preparing a file of treatment information for the state of California. This file is to be sent to external medical researchers. The hospital has removed SSN, name, phone and other information that specifically identifies an individual. However, there may still be data in the file that potentially could identify the individual. Can the hospital claim "safe harbor" and release the file to the researchers?
A State insurance commissioner is requesting specific, individually identifiable information from an insurer as a part of a routine review of the insurer's practices. What must the insurer do to deidentify the information?
The Health Care Claim Status Response (277) can be used in a number of ways. Select the correct usage.
A grouping of functional groups, delimited by' a header/trailer pair, is called a:
Select the correct statement about the 820-Payment Order/Remittance advice transaction.
Select the phrase that makes the following statement FALSE. The 270 Health Care Eligibility Request can be used to inquire about:
This security standard requires that the covered entity establishes agreements with each organization with which it exchanges data electronically, protecting the security of all such data:
Individually identifiable health information (IIHI) includes information that is:
A health care clearinghouse is an entity that:
Establishing policies and procedures for responding to an emergency or other occurrence that damages systems is an example of a(n):
The office manager of a small doctor's office wants to donate several of their older workstations to the local elementary school. Which Security Rule Standard addresses this situation?
The Privacy Rule interacts with Federal and State laws by:
This is a documented and routinely updated plan to create and maintain, for a specific period of time, retrievable copies of information:
The transaction number assigned to the Benefit Enrollment and Maintenance transaction is:
HIPAA establishes a civil monetary penalty for violation of the Administrative Simplification provisions. The penalty may not be more than:
Select the FALSE statement regarding violations of the HIPAA Privacy rule.
The key objective of a contingency plan is that the entity must establish and implement policies and procedures to ensure the:
A doctor is sending a patient's lab work to a lab that is an external business partner. The lab and the doctor's staff are all trained on the doctor's Privacy Practices. The doctor has a signed Notice from the patient. In order to use or disclose PHI, the lab MUST:
Select the FALSE statement regarding the responsibilities of providers with direct treatment relationships under HIPAA's privacy rule.
This Administrative Safeguard standard implements policies and procedures to ensure that all members of its workforce have appropriate access to electronic information.
The Final Privacy Rule requires a covered entity to obtain an individual's prior written authorization to use his or her PHI for marketing purposes except for:
A provider is in compliance with the Privacy Rule. She has a signed Notice of Privacy Practices from her patient. To provide treatment, the doctor needs to consult with an independent provider who has no relationship with the patient. To comply with the Privacy Rule the doctor MUST:
Title 1 of the HIPAA legislation in the United States is about:
Which of the following is NOT a correct statement regarding HIPAA requirements?